Live data from Hacker News

Twitter internal panel linked to account hijackings

vice.com

381–390 of 477 posts

Re: Twitter internal panel linked to account hijackings

#381
post #81

Earlier quoted context omitted.

In the screenshots of the admin panel, it looks like they have blacklists of things that shouldn't show up in searches or on trending. It's not clear if it's accounts, or some other criteria that's blacklisted though.

The account tagged with "trends blacklist" and "search blacklist" was also tagged with "compromised", which suggests that the account was known to be hacked by a malicious actor so it was set to not show up in discovery flows to stop attackers from exploiting it for visibility. Does confirm past claims that they shadowban accounts (which does hide them from search, among other things) at the very least, even if the e…

Are those buttons or tags? Those may be buttons to set "compromised" on an account, etc.

Re: Twitter internal panel linked to account hijackings

#382

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

AT&T claims my security PIN will prevent agents and in store associates from accessing my account. The store rep said there’s no way for him to help me doing anything until we called a special hotline to give my PIN and approval.

Doesn’t mean there isn’t a way around it for some reps with special access. If you don’t have a PIN someone can go and open up multiple new accounts separate from your primary account in your name with different addresses. AT&T won’t even bother to tell you.

Re: Twitter internal panel linked to account hijackings

#383

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

This is why IMO Google has almost no customer service. Their weakest attack vector would be people. Imagine paying your infosec employees hundreds of thousands a year to protect your clients data. Next to them (in terms of data access) is your customer service team at $30,000 per head. Which team is easier to crack?

Re: Twitter internal panel linked to account hijackings

#385
post #184

Earlier quoted context omitted.

How does a single rep coordinate the mass amount of posts across verified (and non verified?) accounts? That is an insane amount of access for 'a rep'. They can just copy and paste the same message across that level of accounts?

The rep can perform a password reset and/or change the sms/email pair and then attackers can do the rest and make the posts themselves.

One rep does password resets for scores of high value accounts?

Re: Twitter internal panel linked to account hijackings

#386

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

If you have a system where customer service reps are strictly unable to access your data without some kind of cryptographic authentication, that defeats the purpose of customer service for 80% of customers (who suck at using computers and mostly just lose their passwords). If you’re in the other 20%, you might as well use some kind of decentralized cryptographic system with no customer service anyway. This is one of…

Yes but you can mitigate the risk by limiting the rate at which any rep can perform security-impacting operations such as password reset, and by denoting high value accounts as requiring additional manual approval.

Re: Twitter internal panel linked to account hijackings

#387

It doesn’t make sense that they could tweet from people’s accounts and get away with it for hours from a moderation panel like that. I don’t buy it.

Was thinking about that. So one scenario, that depends on an API end-point for the internal tool, would immediately and quietly takeover and change account passwords for targetted accounts. After that, start messages from individual accounts. While security is chasing around individual incidents it would take them a while to realize the breach is more systemic. That's probably when they threw the kill switch for verified accounts.

Re: Twitter internal panel linked to account hijackings

#388

Earlier quoted context omitted.

But surely they didn't access the system and post these messages themselves. They could argue, with the advent of remote working getting more and more predominant, that they simply left their computer unattended for a second while logged in. Beyond that, they could argue they simply clicked on a link and something might have happened they aren't aware of. Or that they didn't know what running that one executable woul…

Vaguely plausible excuses will not dissuade prosecutors in possession of contrary evidence.

“I was working remotely at a coffee shop and my computer was swiped while I went to the toilet“ isn’t even plausible given take-out only as well...

Re: Twitter internal panel linked to account hijackings

#389

To me, this raises the likelihood that the attack was about something else. The BTC scam just doesn't seem anywhere near worth it compared to other things you could do - selling or using insider information, blackmail, shorting Tesla, taking out politicians, etc. If the attack had been something like an exploit in the new API, I'd think, maybe some kid found it and was acting fast and reckless. If this was a sophisti…

I think there are three possible explanations here: 1- (Tinfoil hats please) This is a state owned attack, which is a retaliation from US Government to ruin Twitter's credibility and introduce social media regulations. 2- The hackers are gray hat hackers, who know that reporting this vulnerability will not make them any money and they want to get what they think they deserve, so they make it public and get some good…

Another option is that the BTC was nothing but proof that they compromised those accounts. They had full access to the compromised accounts including any private messages. Now there is public proof that they compromised those accounts and a BTC account they can send funds from to prove it is the same group. This allows them to sell those private DMs along with proof of authenticity.

Re: Twitter internal panel linked to account hijackings

#390

> "We used a rep that literally done all the work for us" This is why the privacy and security guarantees of almost all companies, credit bureaus, banks, the IRS, the department of motor vehicles, etc., are worthless. Every customer service rep that works at any of those places -- all 500 or 5000 or 50,000 of them -- can pull up info on anyone at any time. The only thing that prevents that is rules. There are no tech…

Supposedly my credit card company works this way (Chase), though you have to opt in to it when you sign up for two factor authentication. Sprint has the same thing, where they can’t get to anything on my account without passing two measures.

I can’t verify this 100% unfortunately but they are notable because of how rare it is

Post reply on HN